Vulnerabilità · 168 giorni fa

Malicious PDFs Enable Code Execution Across Windows and macOS

A prototype-pollution flaw in Adobe's PDF processing stack allows attackers to execute arbitrary code by delivering malicious PDFs. This breaks the assumption that PDF readers are low-risk utilities since opening a crafted document in common email or file-sharing workflows can lead to full compromise. The standard patching response misses that the delivery vector is everyday business communication, expanding the blast radius beyond just the Acrobat process.

Adobe confirmed active exploitation of CVE-2026-34621 since December 2025, prompting emergency patches for Acrobat DC, Acrobat Reader DC, and Acrobat 2024 on both Windows and macOS. The vulnerability involves JavaScript object manipulation within PDFs, enabling remote code execution. Affected versions include Acrobat DC and Reader DC up to 26.001.21367 and Acrobat 2024 up to 24.001.30356, with fixes in 26.001.21411 and 24.001.30362/30360 respectively.

This vulnerability shows attackers leveraging JavaScript prototype pollution rather than memory corruption, allowing exploitation across multiple OS builds. The risk extends to any user opening untrusted PDFs, making email and document workflows a critical attack surface. The broad deployment of affected Adobe products means this flaw poses an immediate and widespread threat requiring urgent patching.

CVE-2026-34621

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.6 HIGH: acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification… EPSS 2% (82º percentile).

Data di correzione federale CISA 27 apr

Cronologia

Fonti

5 fonti che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-04-14

Editions

Storie correlate